Risk-Adjusted Multifactor Authentication System
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current computer-based authentication systems face challenges in dynamically adjusting security standards based on user risk levels, often relying on static question sets and lacking real-time contextual factors to enhance security.
Innovation Solution
A multifactor authentication system that adjusts authentication standards based on identified risk levels by using a combination of collected, real-time, and observed factors, applying weights to these factors to determine user authorization, and dynamically selecting authentication methods to increase security without additional user input.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the system prompts the user to answer more security questions or to answer security questions with more complex answers to increase security, then the security level is improved, but the user convenience deteriorates
Solution Approach 1:
The authentication system dynamically adjusts the number and complexity of security questions based on the calculated risk level. When risk is low, fewer and simpler questions are presented; when risk is high, more and more complex questions are required. This dynamic adaptation resolves the contradiction by making the security requirement proportional to the actual threat level rather than applying a fixed high barrier to all users.
Solution Approach 2:
The system changes the parameters of authentication (number of questions, complexity level) based on the risk assessment results. The risk level serves as a parameter that determines the authentication stringency, allowing the system to optimize between security and convenience by adjusting these parameters in real-time based on contextual factors.
2Device complexity
If the system uses static question sets for authentication, then the system complexity is reduced, but the adaptability to different risk scenarios deteriorates
Solution Approach 1:
The system transitions from static to dynamic question selection. The question set is no longer fixed but changes dynamically based on the calculated risk level and contextual factors. This allows the system to adapt to different risk scenarios while maintaining manageable complexity through automated risk assessment algorithms.
Solution Approach 2:
The system implements feedback loops where authentication outcomes, user behavior patterns, and contextual information are continuously monitored and fed back into the risk assessment model. This feedback mechanism enables the system to learn and adapt its question selection strategy over time, improving adaptability without requiring manual reconfiguration of the authentication system.
Data Source
AI summary
A computer-implemented method comprising: receiving, from a device used by a user, a request to access a resource hosted by a computer system; identifying, by the computer system, a level of risk associated with the user requesting access to the resource; adjusting, by the computer system an authentication standard for access to the resource, adjusting based on the identified level of risk; determining values for authentication factors used in authenticating the user's access to the resource; applying weights to the values for the authentication factors; and determining, based on a comparison of the weighted values to the adjusted authentication standard, whether the user is authorized to access the resource.


